A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #17978  by thisisu
 Fri Feb 01, 2013 9:41 pm
Topic I am working here was infected by same encryption.

Traces of the ransom but file not found:
Code: Select all
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\oenoxsjo.exe) - File not found
O20 - HKU\S-1-5-21-1177238915-789336058-725345543-1003 Winlogon: Shell - (C:\DOCUME~1\Steve\LOCALS~1\Temp\zrzilhrxsjo.exe) - File not found
Attachments
encrypted
(18.52 KiB) Downloaded 38 times
 #17980  by markusg
 Fri Feb 01, 2013 9:55 pm
In germany we se such infection via e-mail, ask him perhaps for an mail from unknown person with attachment.
 #18033  by thisisu
 Mon Feb 04, 2013 10:47 pm
markusg wrote:In germany we se such infection via e-mail, ask him perhaps for an mail from unknown person with attachment.
I asked. It was from adult website.